← All legal documents

Privacy Policy

Last updated: September 1, 2026

This Privacy Policy explains what data NexusTrinityio LLC ("Nexus Trinity," "we," "us") collects through nexustrinity.io and related services (the "Service"), and what we do with it.

1. Data We Collect

We built this Service to collect as little personal data as possible. Specifically:

CategoryWhat's collectedWhyWhere it's stored
Contract scan requestsThe contract address and chain you query. This is public on-chain data, not personal data.To fetch and analyze the contractSupabase (Postgres), access-restricted
Sanctions Screening requestsThe wallet or contract address you check, and whether it matched. This is public on-chain data, not personal data.To run the check and enforce the free tool's daily limitSupabase (Postgres), access-restricted
Rate-limitingYour IP address, immediately SHA-256 hashed with a private salt — we never store your raw IP.To enforce a fair daily usage limit on the free tools (Contract Reader and Sanctions Screening, tracked separately) and prevent abuseSupabase, as a hash only
Report delivery (optional)Your email address, only if you opt in to receive a report by emailTo send you the report you requestedSupabase + Resend (our email provider)
Lead / "request a review" formName, email, and whatever you write in the message fieldTo respond to your inquiry about audit servicesEmailed to us directly, and/or stored in Supabase as backup
API Access customersEmail, Stripe customer ID, Stripe subscription ID, a hash of your API key (never the raw key after initial issuance), and your two daily quota limits (Contract Reader, Sanctions Screening)To authenticate API requests, enforce your quota, and manage billingSupabase
API usage recordsWhich product (Contract Reader or Sanctions Screening) and address/chain you queried via the API, and whenTo enforce your two daily quotas independentlySupabase, tied to your API key's internal ID only
API overage alertsIf you exceed either daily quota, we're notified by email so we can follow up — your request still succeeds regardless (see the API Terms of Service)To let us proactively raise your limit rather than let you hit a wallResend, sent to us, not to you
Payment informationHandled entirely by Stripe. We never see or store your card number.BillingStripe (not us)
Discord bot usageThe command you ran and its parameters (e.g., a contract address), as sent to us by DiscordTo respond to your /check commandNot persisted beyond what's needed to answer; see §3

We do not require an account or login to use the free Contract Reader or the Discord bot. We do not track you across other websites, and we do not run advertising pixels.

2. How We Use Data

We use the data above only to: operate and improve the Service, respond to inquiries, deliver what you purchased, enforce usage limits and prevent abuse, and comply with legal obligations (e.g., tax records for payments via Stripe).

We do not sell your personal data. We do not share it with third parties for their own marketing purposes.

3. Third-Party Processors

We use the following third-party service providers, each of which processes a limited slice of the data above on our behalf, under their own privacy and security terms:

  • Stripe — payment processing (subscriptions and one-time purchases)
  • Supabase — database hosting (Postgres, with row-level security restricting what's readable)
  • Resend — transactional email delivery (reports, lead notifications)
  • Zoho Mail — outbound outreach email (only to recipients who have not unsubscribed; see §5)
  • Groq — processes contract source code (public, on-chain data) to generate the free-tier Contract Reader analysis. Query text sent to Groq does not intentionally include your personal data.
  • Anthropic — processes contract source code to generate the paid Deep Report analysis (a different, larger-context model than the free tier uses). Query text sent to Anthropic does not intentionally include your personal data.
  • Etherscan (and equivalent block explorers) — source of the public contract source code we analyze
  • Discord — delivers bot interactions; governed by Discord's own privacy policy for anything on their platform
  • Vercel — application hosting

4. Data Retention

  • Hashed IPs and scan records are retained to support rate-limiting and abuse prevention. We do not keep a plaintext log of who visited.
  • Lead form submissions and email addresses tied to a purchase are retained as long as needed to respond to you and for our business records, and can be deleted on request (§7).
  • API usage records are retained to support quota enforcement and are tied to an internal key ID, not directly to your email, in the usage table itself.

5. Email and Opt-Out

If you receive an email from us — a report, a digest, or outreach about our audit services — every message includes an unsubscribe link. Outreach emails are only sent to recipients who have not unsubscribed, and we honor unsubscribe requests immediately.

6. Security

API keys are never stored in plaintext — only a SHA-256 hash, the same approach used for banking and infrastructure API keys industry-wide. The raw key is shown to you exactly once, at issuance. Our database uses row-level security so that even a compromised anonymous credential cannot read or write scan or lead data directly — all writes go through server-side, service-role-authenticated code.

No system is perfectly secure, and we cannot guarantee absolute security of data transmitted to or stored by the Service.

7. Your Rights

You may request access to, correction of, or deletion of your personal data by emailing security@nexustrinity.io. We will respond within a reasonable time. If you are in the EU/UK or a US state with a specific data-rights statute (e.g., California), you may have additional rights under that law — contact us and we will address the request under the applicable framework.

8. Children's Privacy

The Service is not directed at children under 13, and we do not knowingly collect data from them.

9. Changes to This Policy

We may update this Policy from time to time. Material changes will be reflected by an updated "Last updated" date.

10. Contact

NexusTrinityio LLC
security@nexustrinity.io

✉️Email us